Patent · US Active

Enhanced flow-based computer network threat detection

US10855705B2 · kind B2 · utility

2Cited by
9References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 29, 2017
Grant dateDec 1, 2020
Priority date
Expiry dateSep 9, 2038

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/20
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

In one example embodiment, a threat detection server receives metadata of a network flow in a network; a zone definition that correlates the metadata of the network flow with a first zone of network devices in the network and a second zone of network devices in the network, where the network flow was transmitted from the first zone to the second zone; and a security policy for the network flow, where the security policy is enforced on the basis of the first zone and the second zone. Based on the zone definition, the threat detection server annotates a flow record that includes the metadata with an indication of the first zone and the second zone. Based on the annotated flow record and the security policy, the threat detection server determines whether to generate a notification associated with a detection of a security threat associated with the network flow.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.